Can I disable "inspect sqlnet?"

In a recent Cisco Security Advisory (Advisory ID: cisco-sa-20131009-asa) there is a "SQL*Net Inspection Engine Denial of Service Vulnerability" identified.  I plan to follow the upgrade process to resolve this, however, I will not be able to perform the upgrade for a couple of weeks.
The temporary work around suggested is to disable SQL*Net inspection:
ciscoasa(config)# policy-map global_policy
ciscoasa(config-pmap)# class inspection_default
ciscoasa(config-pmap-c)# no inspect sqlnet
This seems simple enough, but I am banging my head on the desk trying to figure out how this will affect any database traffic that may be going through these interfaces.  If the default sqlnet inspection is disabled does that mean I need to add explicit ACL entries per interface to allow that traffic?  I've reviewwed the information from this thread: https://supportforums.cisco.com/thread/2005571
I know there are SQL and Oracle databases on this particular segment, but what confuses me is that there are no rules configured to NAT anything right now.  Is there some sort of way to see if any traffic even matches that default inspection so I know whether it's doing anything right now?
I seem to be overthinking this because I keep going in circles with my own reasoning.  I'm not sure what config information to include with my question.  I can tell you that there are many interfaces in use.  There is no NAT.  There are mulitple security levels. 
Thank you in advance.

Patrick,
Thank you!  This was exactly what I was asking for.  In my post I asked the question "Is there some sort of way to see if any traffic even matches that default inspection." 
That is all I needed.  I don't know why I couldn't find how to show this information.

Similar Messages

  • Advantage/disavantage of disabling "no inspect sqlnet"

    What is the advantage of enabling sqlnet inspection and what is the down side of disabling sqlnet inspection "no inspection sqlnet"?
    I know very well the pro and con of enabling ftp inspection and disabling of ftp inspection but for the past five years, I have not seen anyone has been to explain the pro and con of enabling/disabling sqlnet inspection
    I asked this question five years ago and someone replied but I dont' think he knows what it is.  He just copied from cisco documentation:  https://supportforums.cisco.com/discussion/10838696/what-advantage-enabling-sqlnet-inspection-asa-appliance
    From my production experience, enabling/disabling sqlnet inspection makes no differences and my previous life was an Oracle DBA. 
    I've seen my security vulnerabilities and when Oracle does not work across the ASA firewalls, Cisco TAC response is always "disable sqlnet inspection".
    If that is the case, why have it enable by default in the first place?

    Hi,
    The advantage of having the any protocol inspection enabled on the ASA device is to make ASA device aware of these two things mainly:-
    1) Any Embedded IP address at the application layer for the specific protocol
    2) To allow secondary Channel by opening Pin Holes through the ASA device without explicitly allowing it using the ACL rules.
    Some other inspections are also used to implement/enforce the RFC for the protocols as well (For Ex:- SMTP , DNS etc.)
    Just picking the example from Inspect sqlnet:-
    NoteDisable SQL*Net inspection when SQL data transfer occurs on the same port as the SQL control TCP port 1521. The ASA acts as a proxy when SQL*Net inspection is enabled and reduces the client window size from 65000 to about 16000 causing data transfer issues. Disable SQL*Net inspection when SQL data transfer occurs on the same port as the SQL control TCP port 1521. The ASA acts as a proxy when SQL*Net inspection is enabled and reduces the client window size from 65000 to about 16000 causing data transfer issues.
    http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/i2.html#pgfId-1762719
    These inspections are enabled by default but can be modified or disabled depending on the application that you are using through the ASA device.
    Hope that clarifies your query. Let me know if you have any other questions.
    Thanks and Regards,
    Vibhor Amrodia

  • How can I disable Firefox from automatically opening on system startup on my Mac - unchecking the "open at login" does not work?

    We have Firefox 10.o on our Macbook Pro OS X 10.5.8. I prefer using Firefox as my browser but my husband prefers Safari for now because of a long history of bookmarks and saved information he doesn't have time to re-do. He is tired of Firefox automatically opening when we start up the laptop, and even when we uncheck the "open at login" it still opens at login every time. He is about to uninstall it because of this. How can we disable? It does NOT show up in our account on the Mac OS as an application that starts at login, so we can't disable it there.

    For those of you running Windows, I found this on another site. (Unfortunately, not before getting totally disgusted and switching to chrome.)
    1. click start (or the windows flag button at the bottom left) 2. in the "search programs and files" or the RUN dialog box, enter "msconfig.exe" or "msconfig". 3. That should open the system configuration program. 4. click the "Startup" tab at the top of the opened program. 5. Under the "startup item" column, look for Mozilla firefox. 6. uncheck that one. 7. Click OK or apply. 8. click "exit without restart". 9. you're good to go.

  • How can I disable imessage from old phone?

    how can I disable imessage from old phone number / iphone I no longer have?

    iMesssage to old phone
    If you move to another phone and forget to turn off iMessage then read “if you no longer have the device in http://support.apple.com/kb/HT5661  If you still cannot resolve it call Apple http://support.apple.com/kb/HE57
    To deactivate iMessage http://support.apple.com/kb/ts5185
    Read http://m.samsung.com/us/support/SupportOwnersFAQPopup.do?faq_id=FAQ00053450&fm_s eq=62995

  • How can i disable imessage from automatically starting up when i turn on macbook air?

    how can i disable imessage from automatically starting up when i turn on macbook air? i dont know my imessages to pop up on my laptop when it turns on. But i dont want to disable imessage totally on my macbook.

    Welcome to the Apple Support Communities
    First of all, check that Messages is closed when you turn off your MacBook. This is so important because, by default, OS X will reopen all opened apps the next time you start your Mac.
    Apart from that, when you go to  > Shut Down, or  > Restart, in the window you see to restart or turn off your MacBook, unmark "Reopen windows when logging back in". This will avoid that your Mac opens all opened apps the next time you start the MacBook, so Messages won't start automatically at startup

  • Since updating Firefox as suggested, when I 'save as' a jpeg, it automatically finds the folder and it's always the wrong folder. How can I disable this feature and go back to the original mode where it remains in the folder I choose until I change it?

    For example, I saved a jpeg named 'picasso the guitarist'. I have folders titled A to Z. When I click 'save as' it might open the 'K' folder and I have to manually search the 'P' folder for 'Picasso' and save file. The most irritating thing is, when I 'save as' another jpeg of say 'pieter mother & child' it goes to another folder and does not remain in the 'P' folder, rather it goes to the 'X' folder or some other. This didn't happen before the last upgrade. Can I disable this new 'help' feature that is taking more time than the old version?

    Current Firefox versions remember the download directory based upon the URL, so if the URL changes then the default folder may be chosen if there hasn't been selected a download folder before for that server.
    *[[/questions/889958]]
    *[[/questions/882443]]
    Bug 536503 - Last downloaded-to directory should be remembered on a site-by-site basis
    Firefox 11 will have a workaround by providing a pref (browser.download.lastDir.savePerSite) to disable this feature.

  • Firefox warns about closing tab so as not to loose the content, can I disable this?

    I have various browsing sessions, one is for email, one for studies etc. With one of the browsing sessions when I try to close a tab, firefox asks if I really want to close this tab, because for some reason it thinks I'm writing a message. This is really starting to get on my nerve, not because of firefox, but because of the website that triggers these popups.
    Is there a way to disable these?
    I've trying so hard to find an answer, so I would be really grateful for your help!
    Blessings,
    Janne

    That is caused by a script that run on the page and is triggered by an onbeforeunload event
    *https://developer.mozilla.org/en/DOM/window.onbeforeunload
    *https://developer.mozilla.org/en/DOM/window.onunload
    You probably can't disable such a warning alert, but you can check if you can find a Greasemonkey script to disable such an event
    *void(onbeforeunload = null);
    *Greasemonkey: https://addons.mozilla.org/firefox/addon/greasemonkey/

  • The windows of the Windows bar are already a form of tabs, so I don't need them in Firefox. How can I disable them completely from Firefox 23?

    RE: TABS ARE WINDOWS!
    The Windows bar already functions as a tab bar. Those tabs are called "windows." So, I find Firefox tab windows superfluous. How can I disable them completely from Firefox 23? I don't need what is essentially TWO windows bars covering up the entire width of my widescreen monitor's image! I already have a Windows bar at the bottom of my screen and, if I really wanted to, I could change ITS position to the top of the screen, so that it would LOOK like the Firefox tab windows bar. Firefox TABS are, essentially, a superfluous SECOND WINDOWS BAR.
    Here are my reasons for why I'd rather use Mozilla's Firefox, than Microsoft's Internet Explorer or Google's Chrome. I love and admire Firefox for Mozilla's intent on good security, for Firefox's Personas add-on, and for Firefox's free use of the Ad-Block add-on which, as you know, has the distinct virtue of reducing screen clutter--the last of which is my motive for wanting to get rid of the SUPERFLUOUS Firefox tabs "windows" bar. I am dreadfully sick of companies forcing miscellaneous bars (mostly representing marketing campaigns trying to sell me something) into my browser (and down my throat) every time I download something. (In case you haven't guessed, I am deliberately referring to your Firefox tabs bar as a "Firefox tabs 'windows' bar," because TABS are WINDOWS!)

    Let me clarify even more. The Firefox add-on you mention does not remove "tabs" windows. It only HIDES the "tabs" bar when there is only one "tab" in that window. It DOES NOT end "tabs." It does not turn "tabs" off.
    I know this, because, even with the add-on you recommend, the "tabs" bar often re-appears when I open a link, which--for some unknown reason--Firefox defaults to opening in a second "tab" within the same window, rather than putting it in a new Windows bar window. This, of course, disregards what I want to happen.
    I want to use my Windows bar to control my windows. I do not want my Firefox browser controlling my windows--which it calls "tabs." Can you tell me how to shut off "tabs?"

  • Can I disable an Ipod from ITunes/Other Questions

    Hi all! I am new to this forum and to using IPods/ITunes, so I am still trying to learn as much as I can about them. I made the mistake of getting my very irresponsible young teenage son an IPod (Gen 3) Touch. I have asked him several times to hand the device over to me so I can review the browser’s history (I am not even sure if that is possible, but I was going to try). I am I have major concerns regarding the websites he may be visiting. I am not trying to violate his privacy, but if it was a problem showing me the device - why won’t he hand it over - so that raised some major red flags.
    So...my questions are:
    Can I disable the device from ITunes? Or can I just delete the device from my ITunes Account? Would he still be able to use it?
    I think I found a place on ITune where there was a place I could pick what parental controls that I wanted, I set those up - but I found this feature after he started hiding the device? Can this feature still work remotely without syncing?
    Is there a way to view the browsing and internet history on the device (even if he would delete it)?
    I am not sure if this would make a difference or not to answer my question, but when I had to set up the ITunes account, I did have to provide credit card information to start the account.
    I do have my daughter’s new IPod (Gen 4) Touch also linked to the same ITunes account.
    One more thought...can I just delete the ITunes account totally and start a new one for my daughter? Would this disable his device?
    Again, I am very new to using an IPod. I can get around using them (and selecting the correct features) with a little direction though.
    Thanks for your help and advice in advance it is very very appreciated!
    -SD

    Can I disable the device from ITunes?
    Not without being able to connect the iPod to the computer, no.
    Or can I just delete the device from my ITunes Account? Would he still be able to use it?
    See above.
    I think I found a place on ITune where there was a place I could pick what parental controls that I wanted, I set those up - but I found this feature after he started hiding the device? Can this feature still work remotely without syncing?
    The parental controls feature in iTunes only works for iTunes, not for a portable device. There are similar restrictions on the iPod, but those can only be set on the iPod itself.
    Is there a way to view the browsing and internet history on the device (even if he would delete it)?
    No, sorry, if he clears the history, there's no way to view it.
    can I just delete the ITunes account totally and start a new one for my daughter?
    You can start a new one, but that won't affect any existing accounts. You can change the password on the iTunes Store account he's been using. That would block him from being able to purchase any new content through that account. But you can't stop him from opening up a new iTunes Store account by using a prepaid iTunes card, available from almost any grocery store.
    Would this disable his device?
    No.
    Without being able to have the iPod in your hands, the only way you can affect it would be if you had set up the Find My iPod feature before giving the iPod to your son. If you had, you could then lock the iPod or wipe the data on it. Otherwise, there's nothing you can do until he gives you his iPod, at which time you could set up the Restrictions and, if you wish, download a web browser that allows you to set site restrictions and force him to use that browser.
    Regards.

  • HT204053 Hello I found someone using My Apple ID for face time how can I disable it

    Hello I found someone using My Apple ID for face time how can I disable it

    Welcome to the Apple community.
    Change your password..

  • How can i disable an icon beside battery percentage(a phone on some dots) ?

    AN icon appeared beside battery percentage(iphone 5).its a phone icone on some dots beside battery percentage.how can I disable it?

    iPhone: Understanding the TTY symbol in the status bar

  • How can i disable imessage on my notebook?

    I'm very sick of receiving text messages on every device. How can I disable imessage on my macbook pro so I don't receive texts that I wish to receive only on my phone?

    Welcome to Apple Support Communities
    If you do not want to receive your text messages on your Mac, open Messages, go to Messages menu (in the menu bar) > Preferences > Accounts, choose your iMessage account and untick your phone number or disable your account

  • How can I disable the Mail program from starting automatically on boot?

    Why everytime I start my computer, the Mail program start automatically?...how can I disable this?
    Thanks!

    Control-click its Dock icon and set it not to open at login, or remove it from the list of login items for your user account in the Accounts pane of System Preferences.
    (40415)

  • How can i disable a submit button and execute submit_action method on click

    Good Day,
    On my page I have a submit button that execute the submit_action method of the page backing bean that submit data captured on the page into a database and activate another class that send mail at the same time on a click of the submit button,the mail process takes a while before returning back to the page.I was able to disable the submit button to prevent the user from keep click while the process is running but the issue is on clicking the submit button it only disable the submit button without executing the submit_action method of the page backing bean.How can i disable the submit button and execute submit_method of the backing bean at the same time.
    Thanks in advance.

    I tried this out on one of my pages to see if it works.
    First, I added the following JavaScript to my submit button's onClick event:
    this.disabled=true; return true;When I clicked the submit button, it was disabled but the form was not submitted.
    I deleted the JavaScript from the onClick event and added the following JavaScript to the form's onSubmit event:
    var button = document.getElementById("form1:submitButton"); button.disabled=true; return true;When I click the submit button, it was disabled and the form was submitted but the button's action method was not called.
    The next thing I tried was to change the onSubmit event code:
    var button = document.getElementById("form1:submitButton"); setTimeout("button.disabled=true", 500); return true;This seemed to work. The difference was that I added a 1/2 second delay before disabling the button.
    See if that works for you. If not then I'm fresh out of ideas.

  • How can I disable the Voicemail button on an iPhone 4

    How can I disable the Voicemail button on an iPhone 4 or
    if that is not possible can i programme it to dial my own phone rather than my carrier's Voicemail box?

    No, it's not possible to disable that button and no, it's not possible to reprogram it to anything else.

Maybe you are looking for

  • Error while create aggmap for concatenated dimension ???

    How can I create aggmap for concatenated dimension ?? I created dimensions named awprod_lvl0 ,awprod_lvl1,awprod_lvl2,awprod_lvl3,awprod_lvl4 and concatenated with a dimension awproducts. Then I created a parent relation awproducts.parents and mapped

  • How do I create an application with lots and lots of text?

    I was asked to create an application for the iPad. This application contains a lot of static text. With "a lot" I mean Mb's of text which should be represented in a visual attractive way. One can think of this application as a website but than in app

  • I have a problem creating a pdf from within Firefox using the print to function.

    I have a problem creating a PDF from within Firefox. I get an error message stating that Adobe PDF creation cannot continue because Acrobat is not activated. Acrobat Pro then opens. If it try to create the PDF again, the same problem. I have FF ver 3

  • Current progress in fixing 10.4.6 failed install

    I'm now making some progress in understanding the failiure, however it's leaving me with some BIG questions as to the checks apple put in. This still hasn't fully worked for me! This is also an abbreviated account, please don't try unless your famili

  • Add new VM Server to Existing Pool

    Hi, i have recent deployment of Oracle VM 3.2.2. initially i have created 2 servers in the pool and added a production VM to that. now there is requirement to add one more physical server to existing pool. can any help to me to describe the way to ad